peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,265 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-6344 EXP Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include and execute arbitrary local f… Patch early 6.8 medium 6.1% 2007-12-13
CVE-2009-4367 EXP The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers t… Patch early 6.8 medium 6.1% 2009-12-21
CVE-2022-24181 EXP Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the… Patch early 6.1 medium 6.1% 2022-04-01
CVE-2004-2198 EXP account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId par… Patch early 6.4 medium 6.1% 2004-12-31
CVE-2008-6175 EXP SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to the opendir SFTP command. Patch early 5.0 medium 6.1% 2009-02-19
CVE-2006-5108 EXP Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the… Patch early 6.8 medium 6.1% 2006-10-03
CVE-2006-6564 EXP FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which result… Patch early 4.0 medium 6.1% 2006-12-15
CVE-2006-2929 EXP PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is… Patch early 6.8 medium 6.1% 2006-06-09
CVE-2006-5673 EXP PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to e… Patch early 6.8 medium 6.1% 2006-11-03
CVE-2019-12543 EXP An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter. Patch early 6.1 medium 6.1% 2019-06-05
CVE-2011-0405 EXP Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows remote atta… Patch early 6.8 medium 6.1% 2011-01-11
CVE-2004-1564 EXP CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify ex… Patch early 5.0 medium 6.1% 2004-12-31
CVE-2000-0992 EXP Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 6.1% 2000-12-19
CVE-2000-0056 EXP IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi. Patch early 5.0 medium 6% 2000-01-05
CVE-2004-1101 EXP mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak sensitive p… Patch early 5.8 medium 6% 2005-01-10
CVE-2014-8606 EXP Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files… Patch early 4.0 medium 6% 2015-06-10
CVE-2007-6317 EXP Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..… Patch early 5.5 medium 6% 2007-12-12
CVE-2002-2416 EXP Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request. Patch early 5.0 medium 6% 2002-12-31
CVE-2015-3632 EXP Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a c… Patch early 4.3 medium 6% 2015-05-01
CVE-2015-7707 EXP Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. Patch early 6.5 medium 6% 2015-10-05
CVE-2019-12538 EXP An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field. Patch early 6.1 medium 6% 2019-06-05
CVE-2019-12541 EXP An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter. Patch early 6.1 medium 6% 2019-06-05
CVE-2019-12542 EXP An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter. Patch early 6.1 medium 6% 2019-06-05
CVE-2000-1075 EXP Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary fil… Patch early 5.0 medium 6% 2000-12-11
CVE-2008-5824 EXP Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a denial of service (applicatio… Patch early 6.8 medium 6% 2009-01-02
CVE-2000-0254 EXP The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that… Patch early 5.0 medium 6% 2000-04-14
CVE-2001-0200 EXP HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path… Patch early 5.0 medium 6% 2001-05-03
CVE-2001-0788 EXP Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by… Patch early 5.0 medium 6% 2001-10-18
CVE-2007-4508 EXP Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows r… Patch early 6.8 medium 6% 2007-08-23
CVE-2010-4777 EXP The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debugging enabled, allows context-depe… Patch early 4.3 medium 6% 2014-02-10
← previous page 97 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt